• About
  • FAQ
  • Contact Us
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
Crypto News
No Result
View All Result
Home Market

Malicious npm package secretly targets Atomic, Exodus wallets to intercept and reroutes funds

admin by admin
April 25, 2025
in Market
0
Malicious npm package secretly targets Atomic, Exodus wallets to intercept and reroutes funds
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter



Researchers have discovered a malicious software package uploaded to npm that secretly alters locally installed versions of crypto wallets and allows attackers to intercept and reroute digital currency transactions, ReversingLabs revealed in a recent report.

The campaign injected trojanized code into locally installed Atomic and Exodus wallet software and hijacked crypto transfers. The attack centered on a deceptive npm package, pdf-to-office, which posed as a library for converting PDF files to Office formats.

When executed, the package silently located and modified specific versions of Atomic and Exodus wallets on victims’ machines, redirecting outgoing crypto transactions to wallets controlled by threat actors.

ReversingLabs said the campaign exemplifies a broader shift in tactics: rather than directly compromising open-source libraries, which often triggers swift community responses, attackers are increasingly distributing packages designed to “patch” local installations of trusted software with stealthy malware.

Targeted file patching

The pdf-to-office package was first uploaded to npm in March and updated multiple times through early April. Despite its stated function, the package lacked actual file conversion features.

Instead, its core script executed obfuscated code that searched for local installations of Atomic Wallet and Exodus Wallet and overwrote key application files with malicious variants.

The attackers replaced legitimate JavaScript files inside the resources/app.asar archive with near-identical trojanized versions that substituted the user’s intended recipient address with a base64-decoded wallet belonging to the attacker.

For Atomic Wallet, versions 2.90.6 and 2.91.5 were specifically targeted. Meanwhile, a similar method was applied to Exodus Wallet versions 25.9.2 and 25.13.3.

Once modified, the infected wallets would continue redirecting funds even if the original npm package was deleted. Full removal and reinstallation of the wallet software were required to eliminate the malicious code.

ReversingLabs also noted the malware’s attempts at persistence and obfuscation. Infected systems sent installation status data to an attacker-controlled IP address (178.156.149.109), and in some cases, zipped logs and trace files from AnyDesk remote access software were exfiltrated, suggesting an interest in deeper system infiltration or evidence removal.

Expanding software supply chain threats

The discovery follows a similar March campaign involving ethers-provider2 and ethers-providerz, which patched the ethers npm package to establish reverse shells. Both incidents highlight the rising complexity of supply chain attacks targeting the crypto space.

ReversingLabs warned that these threats continue to evolve, especially in web3 environments where local installations of open-source packages are common. Attackers increasingly rely on social engineering and indirect infection methods, knowing that most organizations fail to scrutinize already installed dependencies.

According to the report:

“This kind of patching attack remains viable because once the package is installed and the patch is applied, the threat persists even if the source npm module is removed.”

The malicious package was flagged by ReversingLabs’ machine-learning algorithms under Threat Hunting policy TH15502. It has since been removed from npm, but a republished version under the same name and version 1.1.2 briefly reappeared, indicating the threat actor’s persistence.

Investigators published hashes of affected files and wallet addresses used by the attackers as indicators of compromise (IOCs). These include wallets used for illicit fund redirection, as well as the SHA1 fingerprints of all infected package versions and associated trojanized files.

As software supply chain attacks become more frequent and technically refined, especially in the digital asset space, security experts are calling for stricter code auditing, dependency management, and real-time monitoring of local application changes.

Mentioned in this article



#Malicious #npm #package #secretly #targets #Atomic #Exodus #wallets #intercept #reroutes #funds

Related articles

Turnkey Announces TRON Policy Engine, Providing Support for Enterprise Payment Solutions

Turnkey Announces TRON Policy Engine, Providing Support for Enterprise Payment Solutions

May 22, 2025
Raoul Pal under fire for calling NFTs the ‘best long-term store of wealth’

Raoul Pal under fire for calling NFTs the ‘best long-term store of wealth’

May 22, 2025
Tags: 000 is bitcoin s practical bottom2 against the minnesota timberwolves adamaffected files and wallet addressesand indirect infection methodsand reinstallation of the walletapril 14 okx saidAtomicbitcoin s surgecode into locally installed atomic andcompare and even thencrypto walletdao announces huge pivot hopes extendingdecoded wallet belonging to the attackerdrop the 25 deltaem bitcoin vix analysisend 1565 blockchainExodusexodus wallet software and hijackedfilm to film though i guessfor ethereum s l2fundsincreasingly many in china are comparingindirect infection methodsinterceptlearning algorithmsmadagascar september 9 2019mainnet integration is complete playersMaliciousnpmof spot bitcoin etfs whichopposition leader peter dutton claimed thepackagepeople heres adam mortonpeople negligible tradereroutesSecretlyseries of high profile rugsolana s high staking yieldsophisticated forms of arbitrage bettingtargetstoken s official x account previouslyWalletswallets to intercept andwas applied to exodus walletwere required to eliminate theyield left vs bitcoin usd right
Share76Tweet47

Related Posts

Turnkey Announces TRON Policy Engine, Providing Support for Enterprise Payment Solutions

Turnkey Announces TRON Policy Engine, Providing Support for Enterprise Payment Solutions

by admin
May 22, 2025
0

Disclosure: This is a sponsored post. Readers should conduct further research prior to taking any actions. Learn more ›NEW YORK...

Raoul Pal under fire for calling NFTs the ‘best long-term store of wealth’

Raoul Pal under fire for calling NFTs the ‘best long-term store of wealth’

by admin
May 22, 2025
0

Raoul Pal, CEO of Real Vision and a prominent voice in macro investing, has once again stirred debate in the...

Solana memecoin average daily volume surges 46% in May, echoing Bitcoin’s recovery

Solana memecoin average daily volume surges 46% in May, echoing Bitcoin’s recovery

by admin
May 22, 2025
0

Memecoin trading activity on Solana is tracking Bitcoin’s recovery, with the average daily trading volume rising 46% between April and...

Active DeFi loans hit all-time high at .7B as TVL nears pre-tariff levels

Active DeFi loans hit all-time high at $23.7B as TVL nears pre-tariff levels

by admin
May 22, 2025
0

Active loans across decentralized lending applications climbed to a record $23.723 billion on May 21, based on Token Terminal data.Meanwhile,...

UK Court of Appeals dismisses BSV lawsuit against Binance, others over 2019 delisting

UK Court of Appeals dismisses BSV lawsuit against Binance, others over 2019 delisting

by admin
May 22, 2025
0

The UK Court of Appeals dismissed a high-profile challenge by BSV Claims Ltd, which sought up to £9 billion in...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

April 25, 2025
Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

May 7, 2025
Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

April 25, 2025
Why DeFi agents need a private brain

Why DeFi agents need a private brain

May 4, 2025
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: 5.55

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
Kraken to Launch 24/7 Tokenized Trading of Apple, Tesla, Nvidia Shares for Non-US Clients

Kraken to Launch 24/7 Tokenized Trading of Apple, Tesla, Nvidia Shares for Non-US Clients

May 23, 2025
Crypto perp futures coming ‘very soon,’ says CFTC’s Mersinger

Crypto perp futures coming ‘very soon,’ says CFTC’s Mersinger

May 23, 2025
Swedish health firm jumps 37% on first Bitcoin buy, China EV seller to buy 1K BTC

Swedish health firm jumps 37% on first Bitcoin buy, China EV seller to buy 1K BTC

May 23, 2025
‘No questions asked’ Bitcoin launderer gets 6 years in prison

‘No questions asked’ Bitcoin launderer gets 6 years in prison

May 23, 2025
  • About
  • FAQ
  • Contact Us
Call us: +1 23456 JEG THEME

© 2025 Btc04.com

No Result
View All Result
  • Home
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
  • Contact Us

© 2025 Btc04.com